Data Processing Addendum
This tawk.to Data Processing Addendum (“DPA”) is between tawk.to Inc., a US corporation with registered offices at 187 East Warm Springs Rd, SB298, Las Vegas, Nevada, 89119, on behalf of itself and its UK affiliate tawk.to Ltd. (“tawk.to”) and the customer that is party to the Agreement, as defined below (“Customer” and, together with tawk.to, each a “Party” and collectively the “Parties”). This DPA prevails over any conflicting term of the Agreement to the extent necessary to resolve the conflict.
(a) “Agreement” means the written or electronic agreement between tawk.to and Customer that governs the provision of data to Customer, as the same may be updated from time to time.
(b) “Controller” means the natural or legal person that, alone or jointly with others, determines the purpose and means of processing Personal Data.
(c) “Data Protection Laws” means all applicable worldwide legislation relating to data protection and privacy which applies to the respective party in the role of the Processing Personal Data in question under the Agreement, including without limitation European Data Protection Laws and other applicable U.S. federal and state privacy laws, in each case as amended, repealed, consolidated or replaced from time to time.
(d) “Data Processor”, “Data Subject”,“Subprocessor”, and “Supervisory Authority” shall be interpreted in accordance with applicable Data Protection Laws;
(e) “Europe” means the European Union, the European Economic Area and/or their member states, Switzerland and the United Kingdom.
(f) “European Data” means Personal Data that is subject to the protection of European Data Protection Laws.
(g) “European Data Protection Laws” means Data Protection Laws applicable in Europe, including: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (“GDPR”); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; and (iii) applicable national implementations of (i) and (ii); or (iv) GDPR as it forms parts of the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”); and (v) Swiss Federal Data Protection Act and its Ordinance (“Swiss DPA”); in each case, as may be amended, superseded or replaced.
(h) “Personal Data” as used in this DPA, means information relating to an identifiable or identified Data Subject who visits or engages in transactions through your store, which tawk.to Processes as a Data Processor in the course of providing you with the Services. Personal Data includes, for example, name, contact information, identification number, location data, online identifier, IP address, as defined in the Data Protection Laws.
(i) “Processing” means any operation or set of operations performed, whether by manual or automated means, on Personal Data or on sets of Personal Data, such as the collection, use, sale, storage, retention, disclosure, analysis, deletion, or modification of Personal Data and includes the actions of a Controller directing a Processor to process Personal Data. “Process” has a correlative meaning.
(j) “UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A(1) of the Date Protection Act 2018 currently found at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf, as may be amended, superseded, or replaced.
2. Scope.
(a) tawk.to is the Processor.
(b) Customer is the Controller.
(c) tawk.to will only Process Personal Data on behalf of Customer in accordance with this DPA and other written instructions of Customer and may not Process Personal Data for purposes or using methods other than those included in Customer’s written instructions, including this DPA.
(d) Customer instructs tawk.to to Process Personal Data as a Processor as outlined in this DPA and in compliance with Data Protection Laws.
(a) Taking into account the nature of Processing and the information available to tawk.to, tawk.to will take reasonable measures to safeguard the security of the Personal Data it Processes as a Processor on behalf of Customer.
(b) Taking into account the nature of Processing and the information available to tawk.to, and insofar as reasonably practical, tawk.to will assist Customer in fulfilling Customer’s obligations under Data Protection Laws by appropriate technical and organizational measures.
tawk.to will notify Customer without undue delay after becoming aware of a Personal Data breach involving Personal Data Processed by tawk.to on behalf of Customer.
(c) tawk.to will not sell or share Personal Data except as instructed by Customer.
(d) tawk.to will not retain, use, or disclose Personal Data it processes on Customer’s behalf for any purpose other than those listed in Annex I to this DPA.
(f) tawk.to will not retain, use, or disclose Personal Data it processes on Customer’s behalf outside of the direct business relationship between tawk.to and Customer.
(g) tawk.to will not combine the Personal Data it processes on Customer’s behalf with Personal Data it receives from or on behalf of another person or persons, or collects from its own interaction with the Data Subject, provided that tawk.to may combine Personal Data as permitted by Data Protection Laws.
(h) In the event tawk.to determines that it can no longer meet its obligations under Data Protection Laws, tawk.to will notify Customer of such determination without undue delay.
(a) Strict Confidence. tawk.to will keep Personal Data, and all information relating to its Processing, in strict confidence. tawk.to will ensure that all personnel authorized to Process Personal Data are subject to a contractual or statutory obligation of confidentiality.
(b) Nondisclosure. tawk.to will not disclose Personal Data Processed on behalf of Customer to any third party without the consent of Customer, or as otherwise provided in this DPA.
(a) Identified Subprocessors. Customer authorizes tawk.to to engage the Subprocessors listed in Annex II to this DPA to Process Personal Data on behalf of Customer.
(b) Additional Subprocessors. Customer further authorizes tawk.to to engage other Subprocessors to Process Personal Data on behalf of Customer after reasonably notifying Customer at least ten (10) days in advance of such engagements.
(c) Appointment Rights. Customer may object in writing to the engagement of a Subprocessor prior to the engagement of the Subprocessor. tawk.to will provide Customer with the information necessary to enable Customer to exercise its right to object.
(d) Subprocessors’ Obligations. If tawk.to engages a Subprocessor to Process Personal Data in accordance with this DPA, tawk.to must enter into a written agreement with the Subprocessor that imposes the same obligations on the Subprocessor as are imposed on tawk.to under this DPA.
(a) When Processing European Data in accordance with Customer’s instructions, Customer is acting as the Controller of European Data (either as the Controller, or as a Processor on behalf of another Controller) and tawk.to is the Processor under the Agreement.
(b) If tawk.to believes that Customer’s instructions infringe European Data Protection Laws (where applicable), tawk.to will inform Customer without delay.
(c) To the extent that the required information is reasonably available to tawk.to, and Customer does not otherwise have access to the required information, tawk.to will provide reasonable assistance to Customer with any data protection impact assessments, and prior consultations with supervisory authorities (for example, the French Data Protection Agency (CNIL), the Berlin Data Protection Authority (BlnBDI) and the UK Information Commissioner’s Office (ICO)) or other competent data privacy authorities to the extent required by European Data Protection Laws.
(d) Transfer Mechanisms for Data Transfers.
(a) Notice. tawk.to will make all notifications, including security-related notifications, required under this DPA as contemplated in the Agreement. Should you require further information, you can make a request to compliance@tawk.to.
(b) Modifications. This DPA may be modified from time to time, at tawk.to’s sole discretion. tawk.to encourages visitors to frequently check this page for any changes to its DPA. Your continued use of the tawk.to services and use of the Site will constitute your acceptance of such change.
(c) Governing Law. The terms of this DPA shall be governed by and interpreted in accordance with the laws of the State of Nevada and the laws of the United States applicable therein, without regard to principles of conflicts of laws. The parties irrevocably and unconditionally submit to the exclusive jurisdiction of the courts of the State of Nevada with respect to any dispute or claim arising out of or in connection with this DPA.
(d) Liability. For avoidance of doubt and to the extent allowed by applicable law, any and all liability under this DPA, including limitations thereof, will be governed by the relevant provisions of the Agreement. You acknowledge and agree that tawk.to may amend this DPA from time to time by posting the relevant amended and restated DPA on tawk.to’s website, available at https://www.tawk.to/terms-of-service/ (https://www.tawk.to/terms-of-service/) and such amendments to the DPA are effective as of the date of posting. Your continued use of the Services after the amended DPA is posted to tawk.to’s website constitutes your agreement to, and acceptance of, the amended DPA. If you do not agree to any changes to the DPA, do not continue to use the Service
(e) Invalidity and Severability. If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision will not affect any other provision of this DPA, and al provisions not affected by such invalidity or unenforceability will remain in full force and effect.
(f) Term. The term of this DPA shall be the same as that of the Agreement.
ANNEX I
Description of Processing
Description of Processing
A. Purpose(s) for Processing:
B. Method(s) of Processing:
1. tawk.to will use Personal Data provided by Customer.
C. Categories of Personal Data Processed:
1. Name, email address, date of birth, address, phone number.
Subprocessors Engaged by tawk.to
Customer authorizes tawk.to to engage the following other Processors:
Subprocessors | Purpose | Entity Country |
Digital Ocean | Data hosting, MTA Email hosting | USA |
AWS Amazon | Data hosting & Sending email | USA, Ireland |
Twilio | Communications technology provider | USA |
Google Inc. | Google Cloud Platform | USA |
Loggly | Cloud Analytics provider | USA |
Apple Inc. | App Store Distribution | USA |
Sendgrid | Sending email | USA |
Cloudflare, Inc. | DNS and CDN | USA |
Pinecone | Vector Database | USA |
PostHog | Customer data analytics | USA |
Microsoft Clarity | Customer data analytics | USA |
Stripe | Payment Provider | USA, Ireland |
Paypal | Payment Provider | USA |
OpenAI | Ai Assitant | USA |